USN-4910-1: Linux kernel vulnerabilities
Ryota Shiga discovered that the sockopt BPF hooks in the Linux kernel could allow a user space program to probe for valid kernel addresses. A local attacker could use this to ease exploitation of another kernel vulnerability. (CVE-2021-20239) It was discovered that the BPF verifier in the Linux kernel did not properly handle signed add32 and sub integer overflows. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-20268) It was discovered that the priority inheritance futex implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3347) It was discovered that the network block device (nbd) driver in the Linux kernel contained a use-after-free vulnerability during device setup. A local attacker with access to the nbd device could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3348) 吴异 discovered that the NFS implementation in the Linux kernel did not properly prevent access outside of an NFS export that is a subdirectory of a file system. An attacker could possibly use this to bypass NFS access restrictions. (CVE-2021-3178)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-4910-1?
The severity of USN-4910-1 is considered high due to its potential exploitation of kernel vulnerabilities.
How do I fix USN-4910-1?
To fix USN-4910-1, upgrade your system to the latest available kernel version as recommended in the advisory.
Who is affected by USN-4910-1?
USN-4910-1 primarily affects users running Ubuntu 20.10 with specific versions of the Linux kernel.
What vulnerabilities are addressed in USN-4910-1?
USN-4910-1 addresses multiple vulnerabilities, including CVE-2021-20239, enhancing the kernel's security against local attacks.
Is it safe to continue using a system with USN-4910-1 vulnerabilities?
It is not safe to continue using a system with USN-4910-1 vulnerabilities, as it could facilitate the exploitation of further kernel vulnerabilities.